logo

Threat Actors Exploit a Critical Ivanti RCE Bug, Again

ID: 95c6f77b-c5bd-5714-91b9-4edd9f92321e

STIX ID: report--95c6f77b-c5bd-5714-91b9-4edd9f92321e

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-01-10

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A suspected Chinese-linked APT (UNC5337) is actively exploiting a critical unauthenticated RCE (CVE-2025-0282, CVSS 9.0) in Ivanti Connect Secure and related gateways to deploy bespoke persistent malware (Spawn family) plus additional scripts (DryHook, PhaseJam); a second authenticated buffer overflow (CVE-2025-0283) was identified but not observed exploited. Ivanti and CISA have issued mitigations and patches; defenders are urged to run Ivanti’s Integrity Checker Tool and patch immediately to detect and remediate compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.